VDB

CVE-2026-20182

CVE-2026-20182 PUBLISHED KEV CVSS 10 CRITICAL

CVE-2026-20182 is a critical authentication bypass affecting the DTLS-based control-connection handshake in Cisco Catalyst SD-WAN Controller and SD-WAN Manager. The flaw exists because, when a connecting peer declares itself to be a vHub device, the system omits device-type-specific certificate verification yet still marks the peer as authenticated. An unauthenticated remote attacker can exploit this by sending a crafted DTLS handshake sequence that bypasses authentication checks and establishes a trusted control-plane peer relationship. Once authenticated, the attacker can issue arbitrary configuration commands across the SD-WAN fabric or establish persistent administrative access. CVE-2026-20224 is an XML External Entity (XXE) injection vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by improper handling of XML External Entity entries during XML parsing. An unauthenticated remote attacker can send a crafted HTTP request to exploit this flaw and read arbitrary files stored on the underlying system, without requiring valid credentials. CVE-2026-20209 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability exists because sensitive session information is recorded in audit logs. An authenticated remote attacker with read-only permissions can retrieve privileged session tokens from those logs and use them to perform actions as a high-privileged user. CVE-2026-20210 is a privilege escalation vulnerability in the web UI of Cisco Catalyst SD-WAN Manager. The vulnerability is caused by a failure to redact sensitive information within device configurations and templates. An authenticated remote attacker with read-only permissions can access this exposed sensitive information and use it to elevate their privileges to those of a high-privileged user.

EPSS 83.13% · 99.3th percentile

Risk Scores

CVSS 3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
83.13%
99.3th percentile

Affected Products

VendorProductVersions
CiscoCisco Catalyst SD-WAN Manager (formerly vManage); all deployment types; releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1
CiscoCisco Catalyst SD-WAN Controller (formerly vSmart); all deployment types (On-Prem, Cloud-Pro, Cisco Managed Cloud, FedRAMP); releases prior to 20.9.9.1, 20.12.5.4 / 20.12.6.2 / 20.12.7.1, 20.15.4.4 / 20.15.5.2, 20.18.2.2, 26.1.1.1

Timeline

  • May 14, 2026 CISA KEV Added
  • May 14, 2026 PoC Published
  • May 14, 2026 CVE Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
  • May 14, 2026 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›